backstreet
BackStreet is a malicious botnet discovered in 2021 by security researchers at Qihoo 360's Netlab, targeting Linux-based IoT devices and web servers. It is a Mirai variant that shares code with the original Mirai botnet but introduces enhanced propagation techniques and a modular architecture for launching DDoS attacks.
BackStreet scans the internet for exposed devices running Telnet (port 23) or SSH (port 22) with default or weak credentials, using a built-in dictionary of over 100 common username/password pairs. Once compromised, the bot downloads a loader component from a remote command-and-control server, which then deploys attack modules capable of launching TCP SYN floods, UDP amplification floods (using DNS, NTP, and SSDP protocols), and HTTP GET/POST floods for Layer 7 DDoS attacks. It also includes a self-propagating worm module that scans random IPv4 addresses to find new victims, and can disable competing malware by killing processes and deleting files. BackStreet uses an encrypted communication channel with its C2 to evade detection, and updates its configuration dynamically via base64-encoded commands. The botnet specifically targets devices running Linux on ARM, MIPS, and x86 architectures, often exploiting unpatched vulnerabilities such as CVE-2017-17215 (Huawei HG532 router remote code execution).
First identified in February 2021 by Netlab, BackStreet was observed attacking multiple targets in Asia and Europe, with peak infected node counts exceeding 10,000. In April 2021, the botnet was linked to a series of DDoS attacks against gaming servers and cryptocurrency mining pools, generating traffic volumes up to 200 Gbps. The malware's codebase was later partially published on a hacking forum, leading to multiple copycat variants. No CVE entries are directly assigned to BackStreet itself, but it exploits existing CVEs like CVE-2017-17215.
Traffic to unusual IP addresses on ports 4433 or 8080 for C2 communication, combined with a high volume of outbound SYN packets to random IPs on ports 23 and 22, are key indicators. The malware uses a unique User-Agent string for its HTTP flood modules: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/87.0.4280.141 Safari/537.36 (spoofed but identifiable). Behavioral fingerprints include rapid Telnet login attempts (over 100 per second) and the creation of files named .backstreet or .ssh_backstreet in /tmp.
Infected devices are fully controlled by the attacker, becoming part of a DDoS botnet that can disrupt critical online services. The worm-like propagation can quickly compromise all vulnerable devices on a local network, leading to data exfiltration of credentials and sensitive configurations stored on IoT devices. Successful attacks can cause extended downtime for websites, gaming platforms, and industrial control systems.
BackStreet is blocked immediately on detection because its autonomous self-propagation and aggressive DDoS capabilities pose an immediate threat to network availability and device integrity. Any observed traffic matching its C2 patterns or brute-force activities triggers automatic firewall blacklisting to prevent further spread.
Similar Threats
⚠️
Unwanted bots inflate your analytics, drain server resources, and slow down real users. Check if your site is affected — completely free.
Check My Site for FreeFree to start · Cancel anytime
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the bots listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.
Stay up to date with the latest from Boteraser.
We use cookies to improve your experience on our site. By using our site, you consent to cookies.
Manage your cookie preferences below:
Essential cookies enable basic functions and are necessary for the proper function of the website.
CloudFlare provides web performance and security solutions, enhancing site speed and protecting against threats.
Service URL: developers.cloudflare.com (opens in a new window)
These cookies are needed for adding comments on this website.
These cookies are used for managing login functionality on this website.
Statistics cookies collect information anonymously. This information helps us understand how visitors use our website.
Google Analytics is a powerful tool that tracks and analyzes website traffic for informed marketing decisions.
Service URL: policies.google.com (opens in a new window)
You can find more information in our Cookie Policy and Privacy Policy.